An in-depth threat actor review published by ThreatMon profiles KillNet — a pro-Russian hacktivist collective that emerged from the Russia-Ukraine war and grew into one of the largest organized cyber militia operations in the world, conducting distributed denial-of-service (DDoS) attacks, targeted intrusions, and credential theft operations against NATO member states, critical infrastructure, government systems, and healthcare organizations across Europe, North America, and Asia.
Origins: A Cyber Militia Born from Geopolitical Conflict
KillNet was formed from the merger of multiple pro-Russian hacker groups in response to the February 24, 2022 large-scale Russian invasion of Ukraine, with an explicit mandate to defend Russia on the cyber front. The group announced a cyber war against Ukraine and all nations supporting it, beginning with DDoS attacks against NATO members. Early operations in May 2022 targeted Romania following its expressions of support for Ukraine, causing Romanian government systems to experience days of outages. Italy was targeted in June 2022, with attacks progressing from website DDoS to the hacking of the Italian Senate and the Italian Automobile Club.
Recognizing that initial DDoS operations were producing insufficient strategic impact, KillNet issued a public call for cyber mobilization on Telegram, recruiting allied groups including f-CkNet, Zarya, RaHDiT, DPR Joker, ZSecnet, XaKNET, Beregini, CyberArmyRussia, Anonymous Russia, and others. The group subsequently reorganized into specialized sub-groups with close operational ties to Russian intelligence services and military units, transitioning from mass disruption to targeted attacks.
Major Operations: 2022–2023
KillNet's campaign record spans multiple high-profile targets across NATO countries and beyond:
- Lockheed Martin (August 2022): The group's first major escalation beyond DDoS — a breach of the world's largest defense contractor that reportedly leaked critical military technology information, employee data, and U.S. Army documents.
- Japan Government (September 2022): Multiple Japanese government websites and systems compromised following Japan's expressions of support for Ukraine.
- U.S. Airport DDoS (October 2022): KillNet targeted airports in 23 U.S. states including Florida and Colorado, disrupting airline traffic, delaying and canceling flights. The campaign was preceded by a Telegram post showing a doctored video of the Statue of Liberty struck by a nuclear weapon, alongside a published list of targeted U.S. states.
- Latvia and White House (November 2022): Latvian government secret documents intercepted and published, followed by prolonged DDoS attacks against the White House website.
- Starlink: Following Elon Musk's redirection of Starlink satellite coverage over Ukraine, KillNet claimed to have compromised the Starlink API system and redirected satellites — with reports that Ukrainian military units halted Starlink use following the incident.
- German Federal Intelligence Agency (February 2023): DDoS against BfV rendered the main domain inaccessible for a sustained period.
- Lithuanian Ignitis Energy Company: Described as the largest cyberattack against Lithuania in a decade, with KillNet announcing continued operations against the state-owned energy provider.
- Healthcare Sector (March 2023): KillNet launched targeted attacks against Western healthcare companies, prompting a DHHS analyst note on threats to the U.S. healthcare industry. A sub-group also claimed access to an Indian government hospital network.
KillMilk Credential Operation
A KillNet-affiliated operator known as KillMilk listed for sale 150 million passwords belonging to residents across Europe, the Americas, Ukraine, and other "unfriendly" countries — a dataset reportedly including bank account passwords, credit and debit card information, cryptocurrency account data, desktop access credentials from approximately 6,000 organizations worldwide, and government portal access.
Technical Profile
KillNet's primary technique remains volumetric DDoS against public-facing infrastructure across ports 21 (FTP), 80 (HTTP), 443 (HTTPS), and 22 (SSH), with documented brute-force activity against these services. Unlike technically sophisticated APT groups, KillNet's operational advantage comes from scale — a large, organized volunteer and recruited network with direct ties to Russian intelligence and military units — rather than novel exploit development. Targeted sectors include government, defense and weapons, healthcare, technology, and aviation/airport infrastructure across NATO member states.